Re: [v6ops] I-D An Extension to DNS64 for Sender Policy Framework SPF Awareness

Mark Andrews <marka@isc.org> Tue, 15 February 2022 03:48 UTC

Return-Path: <marka@isc.org>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 08EF83A0A80 for <v6ops@ietfa.amsl.com>; Mon, 14 Feb 2022 19:48:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=isc.org header.b=QlLAujRs; dkim=pass (1024-bit key) header.d=isc.org header.b=o1XkW5PJ
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ewOmEbNcUcno for <v6ops@ietfa.amsl.com>; Mon, 14 Feb 2022 19:48:43 -0800 (PST)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [149.20.64.53]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4D3673A0A7D for <v6ops@ietf.org>; Mon, 14 Feb 2022 19:48:42 -0800 (PST)
Received: from zimbrang.isc.org (zimbrang.isc.org [149.20.1.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx.pao1.isc.org (Postfix) with ESMTPS id C9FA13AB009; Tue, 15 Feb 2022 03:48:41 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 mx.pao1.isc.org C9FA13AB009
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=isc.org; s=ostpay; t=1644896921; bh=IwydvM37Iu4AFJQzPKr8cjH1rBN7e9s9kDSu46DbgmU=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=QlLAujRs1KHw9CqiEVlvz4xWh7EkT3j8iaiCzNtVT/uvLbnX7EKuALVhrxv/Ag9uT bOyuQW9HUSuxogDctPZOfcxDP/pCPv/bym4TMOstn24eaXc/VB7jomRzA3sz+a8XWc u9LsDZ8AuL0cpwj61P0Ba/AgPQlRUKCxYzOnNBO0=
Received: from zimbrang.isc.org (localhost.localdomain [127.0.0.1]) by zimbrang.isc.org (Postfix) with ESMTPS id B9C70FE8269; Tue, 15 Feb 2022 03:48:41 +0000 (UTC)
Received: from localhost (localhost.localdomain [127.0.0.1]) by zimbrang.isc.org (Postfix) with ESMTP id 80332FE826D; Tue, 15 Feb 2022 03:48:41 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 zimbrang.isc.org 80332FE826D
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isc.org; s=05DFB016-56A2-11EB-AEC0-15368D323330; t=1644896921; bh=yuQIf5PGuMzrRNEc8/F2+Y+MabttzLh76Aa588DsKPg=; h=Mime-Version:From:Date:Message-Id:To; b=o1XkW5PJfvr0+yE+nHWnQOcvGGXIZuxPjo84dnXXBP4wPwZggVbMiJ88B/pZ43gEh HMXSJK4X/90pJvDfx8sYr3TWfXpprxtMgiUnmuWeqPHCKdXdum7Gu0SyQqV2w5/L2N FjpVwHELMjwTqcvCUzjW5lIaIm1FsgLhP8LT+pzI=
Received: from zimbrang.isc.org ([127.0.0.1]) by localhost (zimbrang.isc.org [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id AFD-M2nfioWm; Tue, 15 Feb 2022 03:48:41 +0000 (UTC)
Received: from smtpclient.apple (n114-74-26-107.bla4.nsw.optusnet.com.au [114.74.26.107]) by zimbrang.isc.org (Postfix) with ESMTPSA id CB282FE8269; Tue, 15 Feb 2022 03:48:40 +0000 (UTC)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.13\))
From: Mark Andrews <marka@isc.org>
In-Reply-To: <dba71317-3889-7b0a-c9fa-2a907bb40e93@posteo.de>
Date: Tue, 15 Feb 2022 14:48:37 +1100
Cc: v6ops@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <32A108DF-E4B9-4D54-82FE-90B95C7BCB42@isc.org>
References: <dba71317-3889-7b0a-c9fa-2a907bb40e93@posteo.de>
To: Klaus Frank <klaus.frank@posteo.de>
X-Mailer: Apple Mail (2.3654.120.0.1.13)
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/zLFb4fchtuZwtLK2iTshzOgfFeE>
Subject: Re: [v6ops] I-D An Extension to DNS64 for Sender Policy Framework SPF Awareness
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Feb 2022 03:48:48 -0000

As I noted in dnsops, there is no way for the DNS64 resolver to achieve the aims of this draft when the SMTP client
is dual stacked.  Handling a: and mx: methods depend on A’s being mapped to AAAA which does not happen for dual
stacked clients with DNS64.  The presence of the AAAA records will stop AAAA’s being synthesised from A records.

Mark

> On 14 Feb 2022, at 19:53, Klaus Frank <klaus.frank@posteo.de> wrote:
> 
> Hi,
> 
> I wrote an I-D for updating DNS64 to better work for MTA operators. I'd like to get your opinions on that as some guidance on how to move forward with it (sorry I'm new to the process). Some background for this we had some issues with SPF and a mail server that was behind NAT64+DNS64. I at first thought that it was just a misconfiguration. But after the DNS64 server seamed to work as intended I went to the implementation and the RFC. Thereby while reading RFC6147 I stumbled across section 5.3.3 which says "All other RRs MUST be returned unchanged." which is the cause of my issues. This section is basically ignoring SPF records (RFC7208 section 5.6) and also preventing DNS64 implementations from addressing this limitation themselves. After some discussion on the behave and spfbis mailing list I created this I-D. I was referred to this mailing list as both the behave as well as the spfbis WG are closed.
> 
> GitHub: https://github.com/agowa338/IETF-RFC-drafts/blob/main/draft-frank-dns64-spf-extension-03.xml
> 
> Sincerely,
> Klaus Frank
> 
> Name:        draft-frank-dns64-spf-extension
> Revision:    03
> Title:        An Extension to DNS64 for Sender Policy Framework SPF Awareness
> Document date:    2022-02-14
> Group:        Individual Submission
> Pages:        6
> URL: https://www.ietf.org/archive/id/draft-frank-dns64-spf-extension-03.txt
> Status: https://datatracker.ietf.org/doc/draft-frank-dns64-spf-extension/
> Html: https://www.ietf.org/archive/id/draft-frank-dns64-spf-extension-03.html
> Htmlized: https://datatracker.ietf.org/doc/html/draft-frank-dns64-spf-extension
> Diff: https://www.ietf.org/rfcdiff?url2=draft-frank-dns64-spf-extension-03
> 
> Abstract:
>    This document describes interoperability issues and resolutions
>    between DNS64 and SPF records for mail transfer agents.  This
>    document also aims to simplify the IPv6 migration for mail transfer
>    agent operators.
> 
>    This document updates [RFC6147] and [RFC7208].
> 
> _______________________________________________
> v6ops mailing list
> v6ops@ietf.org
> https://www.ietf.org/mailman/listinfo/v6ops

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka@isc.org